name: Release # Tag pushes mirrored from Gitea (git.jezz.wtf) trigger this on the GitHub # mirror. Builds the NSIS installer and attaches it to a DRAFT GitHub Release — # review and publish manually. on: push: tags: - 'v*' workflow_dispatch: jobs: release: permissions: contents: write runs-on: windows-latest env: GITEA_STATUS_TOKEN: ${{ secrets.GITEA_STATUS_TOKEN }} steps: - name: Report pending status to Gitea if: env.GITEA_STATUS_TOKEN != '' continue-on-error: true shell: pwsh env: GITHUB_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} run: | $headers = @{ Authorization = "token $env:GITEA_STATUS_TOKEN" Accept = "application/json" } $body = @{ state = "pending" context = "github/actions/release" description = "GitHub Actions release is running" target_url = $env:GITHUB_RUN_URL } | ConvertTo-Json Invoke-RestMethod ` -Method Post ` -Uri "https://git.jezz.wtf/api/v1/repos/JezzWTF/phokus/statuses/$env:GITHUB_SHA" ` -Headers $headers ` -ContentType "application/json" ` -Body $body - uses: actions/checkout@v4 - uses: pnpm/action-setup@v4 with: version: 11 - uses: actions/setup-node@v4 with: node-version: 22 cache: pnpm - name: Install Rust stable uses: dtolnay/rust-toolchain@stable - uses: Swatinem/rust-cache@v2 with: workspaces: src-tauri - name: Install frontend dependencies run: pnpm install --frozen-lockfile - name: Build and create draft release uses: tauri-apps/tauri-action@v0.6.2 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Updater artifact signing (Phase 3) — set these repo secrets once # the updater keypair exists; empty values are ignored until then. TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }} TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }} with: tagName: ${{ github.ref_name }} releaseName: 'Phokus v__VERSION__' releaseBody: 'See the assets below to download and install this version.' releaseDraft: true prerelease: false includeUpdaterJson: true updaterJsonPreferNsis: true # Cargo args after `--`: ship the CPU/DirectML build — default # features enable candle-cuda, which runners (and most users) lack. args: '-- --no-default-features' - name: Report final status to Gitea if: always() && env.GITEA_STATUS_TOKEN != '' continue-on-error: true shell: pwsh env: GITHUB_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} JOB_STATUS: ${{ job.status }} run: | $state = switch ($env:JOB_STATUS) { "success" { "success" } "failure" { "failure" } default { "error" } } $headers = @{ Authorization = "token $env:GITEA_STATUS_TOKEN" Accept = "application/json" } $body = @{ state = $state context = "github/actions/release" description = "GitHub Actions release finished: $env:JOB_STATUS" target_url = $env:GITHUB_RUN_URL } | ConvertTo-Json Invoke-RestMethod ` -Method Post ` -Uri "https://git.jezz.wtf/api/v1/repos/JezzWTF/phokus/statuses/$env:GITHUB_SHA" ` -Headers $headers ` -ContentType "application/json" ` -Body $body